Securing organisations shouldn’t be expensive
In times of austerity, reduced budgets and increasing regulation, all organisations need to consider innovative ways to consistently provide good levels of service whilst reducing costs.
‘Cloud’, ‘outsource’, ‘agile’ and ‘collaboration’ are terms we have all come to know and understand to varying degrees. They have also changed our ways of thinking when procuring services and technology. But while there are many advantages to these different types of solutions, it is also essential to understand what impact they have on data security.
The requirements to protect personal data of consumers has not changed. The Information Commissioner’s Office (ICO), continues to fine companies and government bodies for failing to secure customer data, whilst under their control.
You may also need to protect sensitive organisation data in line with regulatory mandates or corporate policies, when it can be accessed or used by external organisations.
So, how can you deliver savings whilst understanding the risks concerned?
By defining and embedding your security requirements within the procurement process and ensuring efficient on-going management of your supply chain, you can effectively transfer risk to suppliers and ensure the appropriate level of data security, while continuing to unlock savings via innovative solutions.
In the following, CSP provides a high-level view of the steps required to secure both savings and data, together with some do’s and don’ts for smarter procurement:
Designed in Security
Our experience shows that IT projects have considered data security to a greater or lesser extent. However, even non-IT projects can require customer data, to leave the direct control of their organisation for transfer to the third-party supplier.
Do
- Review the procurement process to ensure that the correct teams are involved from the beginning, and that the appropriate security steps are included.
- Engage with internal teams to ensure that data protection is considered in ALL projects.
- Assess the criticality of the data: How important is the data? How sensitive? Classify the data to ensure the focus is on the right projects.
Don’t
- Assume that security can be added in later. Options that are readily available at the start of a project may no longer be available, after initial decisions have been taken without wasting substantial effort.
- It is also often more expensive to include security controls at a later point in the project lifecycle, given the re-work and contractual changes required.
Define clear requirements
The real issue for securing customer and organisational data is whether you have the right security in place to manage the risk.
Robust data protection and information security is about balancing security controls (People, Process, Technology) with your business goals. Why implement an expensive technical solution, when an annual all-staff training session will suffice? Why move to larger offices if you can securely work from home? Why purchase extra laptops if employees can use their own PCs at home?
By defining the right control requirements, procurement teams can gain significant cost-savings by focusing the more expensive controls in the right place.
Do
- Use generic, organisation-wide security requirements as the starting point. Custom security requirements are not needed for all projects. Often a standard list will suffice – as these will probably address 80% of the data protection controls requirement.
- Propose extra control requirements for only the most sensitive of data, or the higher volumes. Time and effort should be spent on these exceptional requirements to determine whether you would like additional controls to meet internal and corporate standards.
Don’t
- Consider a technical solution as a catchall able to address all your concerns. These can be very expensive, and a simple process control may be as good and nearly as effective.
- Assume that suppliers are aware of their responsibilities regarding data protection. As data con- trollers you are responsible for ensuring that the suppliers handling the data you have collected are aware of their responsibilities. Define clear responsibilities and compliance statements within the requirements.
Contract with embedded security
Specific security clauses and statements should be included in all contracts that clearly define the roles and responsibilities of each party. Whilst establishing a circle of trust with your suppliers is key to an efficient supply chain, there must be a contract in place that clearly defines the official position of the relationship in case the worse should happen.
Do
- Specifically state the roles responsible for data protection within all contracts and establish rules for communication. Clear communication channels allow trusted suppliers to openly discuss security controls and ensure on-going compliance with legislative requirements that are subject to change.
- Include pass through security statements in the contract so that any outsourcing by your suppliers will not weaken your security position. Your third party-supplier may choose to outsource some of their supply chain, if that involves your information, then it must also be protected in line with your requirements.
Don’t
- Assume that supply chain security in place today will still be implemented tomorrow. Include statements within the contract that stipulate continued compliance with security requirements. Changes to supplier circumstances or controls later will not remove any of the security requirements (or crucially, liability should litigation ensue).
Assess suppliers for security
The advantages of a trusted supply chain are many; cost savings, reliability, scalability, and many more. However, not all outsourced services are able to offer the same levels of security, no matter how established they are. Even security offerings between companies in the same industry sector – e.g., a Cloud Service Provider, can differ significantly.
Certification to international standards can help, assuming the all-important scope has been defined properly, but sometimes an assessment is required to provide confidence in the controls being offered. This is particularly relevant where small or medium sized suppliers may not have the resources or skill to meet the standards.
Do
- Include statements so that potential suppliers can complete self-assessments. Making most information assessments the responsibility of suppliers, frees up your time to manage more contracts securely.
- Draw up an assessment plan that reflects data criticality. Assessments can’t and shouldn’t be completed on every supplier. This would take up too much time and internal resource. A prioritised plan, based upon data criticality, confidence required and/or incidents within the last year, must all be factored in.
Don’t
- Assess the security of the entire supplier – focus on the controls that are in place to protect your information.
- Forget to include the option for assessing suppliers within the contract, or prior to signature. Whilst this option may never be taken up, obtaining agreement from the outset encourages an open approach between supplier and consumer.
Monitor compliance
Even with all the best controls in place, you can’t rely solely upon the above steps, then sign the contract and let it run.
Do
- Develop a framework of trust with suppliers. Transparency between all parties on the security of the data allows the processes and the business of the organisations involved, to operate smoothly.
- Request that suppliers confirm the status of their own controls on a regular basis. Include regular Key Performance Indicators (KPIs) and compliance reports throughout the life of the contract.
Don’t
- Assess all of your suppliers all of the time. Focus on those suppliers with sensitive or large volumes of data.
- Assume that the security level provided by all of your suppliers will stay the same throughout the course of the contract. Develop incident reporting processes to enable rapid responses to any security incidents.
So…
CSP can show you how to transfer risk to suppliers and manage them effectively while making savings without compromising security.
We can help you reduce the cost of your supplier assessments whilst achieving a standardised approach to security requirements, that can be applied consistently over the long term. CSP can:
- Review the procurement process to ensure the right checks and balances and appropriate security steps are designed-in
- Help you define both general supplier security requirements for use across all types of projects, and a specific set of security requirements tailored to the type of data your potential suppliers will process
- Provide detailed legal statements for security within the contract, and review current framework suppliers to understand potential risk exposure
- Perform security assessments of suppliers to confirm their security position against international standards or internal requirements, as well as IT Health Checks and penetration testing to confirm security of their network and systems
- Provide a bespoke management tool that enables all organisations to manage suppliers and their compliance status internally
